T08 · Insecure Dependencies
- Location
SKILL.md:757- Finding
Unpinned Execution of a Credentialed Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:280-288,SKILL.md:318-323,SKILL.md:757-759;README.md:156-173,README.md:242
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: MediumVulnerable Code Snippets
SKILL.md:280-288:markdown ### Optional MCP server provenance (`codivupload-mcp`) - Official package: [`codivupload-mcp` on npm](https://www.npmjs.com/package/codivupload-mcp), maintained by Codivion LLC, source at [github.com/Codivion/codivupload-mcp](https://github.com/Codivion/codivupload-mcp). - **Always use an exact version pin** for credentialed runtimes — not `^`, not `~`, not `latest`. - Currently reviewed pinned version: `2.0.0` - Publisher (verify): `codivion <accounts@codivion.com>` — `npm view codivupload-mcp publisher` - Integrity sha512 (verify): `pK0r8XkR2M/brfn1Nsy6Uh7nGDx5qpx9h3pLgZljYkU3pv0BXKb7uJapBOFL11mBIQhWAl0hASxxCSLE11SDfA==` — `npm view codivupload-mcp@2.0.0 dist.integrity` - Install command: `npm install -g codivupload-mcp@2.0.0` - **Avoid `npx -y codivupload-mcp` without a pinned version** — the `-y` flag auto-accepts any version that resolves, which is a bad fit for a credentialed runtime. - The MCP server inherits the API key from your OpenClaw config — no separate credential surface, but the inheritance is why the version pin matters: a compromised future release would receive your live `CODIVUPLOAD_API_KEY`.SKILL.md:318-323:markdown **Optional companion package:** - `codivupload-mcp` (npm) — drop-in MCP server. **Use an exact version pin** (no caret, no tilde, no `latest`): - Reviewed pinned version: `2.0.0` - Publisher: `codivion <accounts@codivion.com>` (verify with `npm view codivupload-mcp publisher`) - Tarball integrity (sha512): `pK0r8XkR2M/brfn1Nsy6Uh7nGDx5qpx9h3pLgZljYkU3pv0BXKb7uJapBOFL11mBIQhWAl0hASxxCSLE11SDfA==` (verify with `npm view codivupload-mcp@2.0.0 dist.integrity`) - Install: `npm install -g codivupload-mcp@2.0.0` — ...[truncated 4754 chars]- Remediation
View remediation
Remediation Suggestions
- Replace every floating invocation with an exact version:
bash npx --yes codivupload-mcp@2.0.0- Pin SDK references as well:
bash npm install codivupload@<reviewed-version> pip install codivupload==<reviewed-version>-
Remove or revise
README.md:242andSKILL.md:759so they cannot override the otherwise consistent pinning guidance. -
Avoid global installation where possible. Run the package in an isolated environment with:
- A dedicated unprivileged operating-system account
- Minimal filesystem access
- Egress restricted to documented CodivUpload endpoints
- No unrelated environment variables or credentials
- A single-platform or per-workspace API key
-
Make integrity verification enforceable rather than advisory:
- Download the exact package tarball without executing it.
- Calculate its SHA-512 digest locally.
- Compare it with a trusted digest stored in the reviewed Skill.
- Abort on any mismatch.
- Execute only the verified artifact.
-
Prefer a lockfile-backed local installation over
npxregistry resolution. Commit the package name, exact version, resolved URL, and integrity metadata. -
Audit the external MCP package independently because its source is outside this project. Repeat that review before changing the pinned version.
-
Rotate
CODIVUPLOAD_API_KEYimmediately if an untrusted package version has run. Review API activity and connected social accounts for unauthorized actions. -
Keep the MCP package optional and prefer direct, narrowly scoped REST calls when MCP functionality is unnecessary.
